
Report It, and Qualimetrix Will Answer.
Qualimetrix accepts security reports about its suite, its site and its infrastructure. Reports are acknowledged, scoped and answered, and a reporter acting in good faith is not pursued.
Where to report
Send reports to compliance@qualimetrix.nl with the subject line Responsible disclosure. [PGP key to confirm.] Do not include production data, personal data or credentials belonging to third parties.
What to include
The affected component or URL, the steps to reproduce, the impact you observed, and the date and time of testing. A short proof of concept is welcome; a full exploit chain is not required.
What Qualimetrix commits to
Acknowledgement within [period to confirm]. An in-scope or out-of-scope decision, with reasons. Progress updates until the report is closed, and confirmation when remediation ships.
Safe harbour
A reporter who acts in good faith, stays within scope, avoids privacy violations and data destruction, and gives Qualimetrix reasonable time to remediate will not face legal action from Qualimetrix for the research.
Out of scope
Denial of service, physical attacks, social engineering of staff or customers, automated scanner output without a demonstrated impact, and reports concerning third-party services Qualimetrix does not operate.
Disclosure timing
Coordinated disclosure after remediation, or after [period to confirm] if remediation is not possible. Qualimetrix will credit a reporter by name on request and will not publish a reporter’s identity without consent.
Draft text for legal review. Bracketed items require confirmation before publication. This is not legal advice.